Case file
- What happened: Weeks after the April 1990 launch, NASA found Hubble's 2.4 m primary mirror ground with spherical aberration – its edge too flat by roughly 2.2 microns – producing blurred images.
- Scale: The most capable optical telescope ever orbited returned star images wrapped in halos; no focus adjustment could reconcile the mirror's centre with its edge.
- Root cause: The Perkin-Elmer reflecting null corrector used to certify the mirror had its field lens about 1.3 mm out of position. Two simpler cross-check instruments disagreed with it during fabrication and were explained away, not escalated.
- The bill: Roughly $850 million for the December 1993 STS-61 servicing mission – eleven days, seven astronauts, five spacewalks – to install COSTAR optics and the WFPC2 camera, fully restoring the telescope.
Here is an uncomfortable observation for anyone who signs test reports for a living: Hubble's mirror was flawless. Polished to a precision the optical world had rarely achieved, certified by every interferogram – because every interferogram looked through the same misplaced lens. The product agreed perfectly with its gauge. The gauge lied. Two decades on shop floors have taught me that diligence aimed at an unverified reference is the most expensive failure class there is.
The situation
NASA contracted the optics in the late 1970s, with Perkin-Elmer shaping the 2.4 m primary – the most demanding optical element ever attempted for orbit. A fast conic mirror of that size cannot be tested at focus inside a factory, so the company built a reflecting null corrector: an arrangement of mirrors and lenses that synthesised a perfect reference wavefront and made the aspheric surface readable to shop interferometers. That rig became the arbiter of truth for every polish pass.
The arbiter itself was never judged.
How it unfolded
Hubble reached orbit in April 1990. The first images came back soft. Engineers chased the mundane suspects – thermal settling, focus trim, outgassing – until NASA confirmed spherical aberration in June: light from the mirror's centre and edge focused at different points, smearing every star into a halo.
The traceback, laid out afterwards in the Allen Commission's report, is the painful part. During fabrication two simpler cross-check instruments disagreed with the primary corrector; both results were set aside as inferior equipment rather than treated as signal. The rig's own assembly records contained a spacing measurement flagging exactly the error later confirmed, and that too was blamed on the measuring method. Nobody put those pieces together until the telescope was already in orbit. STS-61 flew in December 1993 – eleven days, five spacewalks – installing WFPC2, a replacement camera with correction built into its optics, and COSTAR for the remaining instruments. Capability was fully restored, three and a half years later.
Root-cause anatomy
Technically this was not a polishing failure. The surface figure was exquisite. It was a reference failure. A null corrector works by simulation: it defines what "correct" means. Put the field lens 1.3 mm off its station and the simulation quietly redefines the target; the mirror follows at full precision. An unverified measurement artefact propagates its own error into the product at unity gain.
Organisationally, the Allen Commission traced strands any 8D team would recognise. Schedule and cost pressure crowded out cross-verification. NASA's oversight of Perkin-Elmer concentrated on budget and milestones, not the technical basis of acceptance. The culture assumed the most sophisticated instrument must be right; when humbler devices disagreed, authority beat evidence. No independent-method check of the reference was ever run, and a full end-to-end optical test of the assembled telescope was skipped, partly on cost. The backup mirror, ground by Kodak and verified by independent means, carried no such error. That contrast convicts.
Where the quality system failed
Name the disciplines, because each failure had a formal home. Measurement system analysis: the null corrector was a gauge, and no MSA ever treated it as one – a VDA 6.3 auditor would ask to see its qualification against an independent method, and no such qualification existed. PFMEA: the polishing process was analysed exhaustively, but the measurement device never earned a failure-mode line of its own, never mind severity 10 for "reference wrong, every part accepted". Escalation: two dissenting instruments are an Andon pull in any healthy system; here the disagreement was arbitrated away instead of contained. Supplier quality: NASA accepted results generated by the very instrument it should have been auditing.
A gauge nobody is allowed to challenge is not a measurement – it is an opinion with a calibration sticker.
What would have caught it
Nothing here needed inventing. It needed scheduling.
- Independent-method verification. Qualify the null corrector against a physically different method – refractive against reflective – before the first polish pass. Kodak's backup mirror proves the approach worked.
- A disagreement gate. Two measurement systems out of tolerance with each other stop the line, automatically, and the arbitration never belongs to the owner of the favourite instrument.
- Measurement lines on the PFMEA. Wrong reference, severity 10, detection 1.
- Change control on the rig. Reassemble the corrector and it loses the status of truth until re-verified.
- End-to-end acceptance. One full-aperture test of the assembled optics at handover would have exposed the aberration no matter which gauge lied.
My take
My career runs on the low-altitude version of this problem. Two decades of supplier audits under VDA 6.3 and IATF 16949, and my first stop has always been the gauge room, not the line; my first question, who checks the checker. Building a QA function from scratch for a 900-plus-employee greenfield plant, we made MSA and an independent cross-check a launch gate – no verified reference, no start of production. I have chaired QRQC sessions that ended exactly where Perkin-Elmer's process never began: two instruments disagree, we stop, the gauge stands accused until proven otherwise. I have never had to fix anything at orbital altitude, and I buy redundancy early to keep it that way. The second measurement method costs four figures. The failure it prevents – sorting, containment, customer escalation – never has.
What this means on your floor
- Disagreement between two gauges is free defect information. Escalate it; do not arbitrate it away.
- Qualify reference standards against an independent method before they earn the authority to accept product.
- Give measurement equipment its own failure modes on the PFMEA – a wrong reference passes bad parts with perfect confidence.
- Whoever owns the most trusted instrument must never be the one who dismisses its dissenters.
Hubble's mirror was not a failure of skill but of the assumption that skill exempts you from verification. Perkin-Elmer made something perfect and never asked what perfect was measured against. COSTAR and WFPC2 repaired the optics in 1993. The durable corrective action is the one available tomorrow morning: when an instrument disagrees with your assumption, the instrument has done its job. Stop the line. Check the checker.